What not to put in ProjectPacer

ProjectPacer isn't built for sensitive or regulated information — here's what to keep out, and why.

ProjectPacer is a general-purpose time tracker. It is not designed, sold, or configured for sensitive or regulated information — and in particular it is not HIPAA-compliant and we do not sign Business Associate Agreements (BAAs). Keep that kind of data out.

Not for protected health information (PHI) or other sensitive data

Don't put names of patients or clients tied to a health condition, diagnoses, treatment details, Social Security or other government ID numbers, payment card numbers, or anything similarly sensitive into ProjectPacer — in entry descriptions, task titles, project or client names, or connected calendar events.

The one to watch: connected calendars

Most fields in ProjectPacer only ever contain what you type. A connected calendar is different — it pulls in your event titles and attendees automatically, and a clinical or health-services calendar routinely carries a patient's name right in the event title.

So before you connect a calendar feed: if its events could contain sensitive or health information, don't connect it. Point ProjectPacer at a work calendar that doesn't, or track that time manually instead. We show this same reminder at the moment you add a feed.

If something sensitive lands in anyway

You're always in control of your own data:

  • Delete any entry or description at any time — fixing a bad paste is one click, not a support ticket.
  • Turn a signal source off and its stored timestamps are deleted (see what we collect).
  • Export or delete your data whenever you like.

Why we draw this line

Handling regulated data like PHI means legal obligations (a signed BAA, breach-notification timelines, audited controls) that a general-purpose time tracker deliberately doesn't take on. Staying out of that scope is what lets us keep ProjectPacer simple — and it keeps you from unknowingly routing regulated data through a tool that isn't set up to carry it. If your work involves PHI, use a system your organization has cleared for it, and keep ProjectPacer to the non-sensitive record of your time.

This isn't legal advice

This page describes how we intend ProjectPacer to be used. Your organization's own policies and any agreements you're under govern what you may put where — check with your compliance or legal contact if you're unsure.

Was this helpful?
Still stuck? Contact support and we'll help.